m365expertise MICROSOFT SECURITY EXPERTISE

Entra ID & M365 blog

The 18 articles that cover Entra ID & M365. The methodology and compliance ones apply to the two other referentials as well; the rest are specific to EntraGUARD.

Security

Mapping the simulated attacks to MITRE ATT&CK

Every simulated attack links to its MITRE ATT&CK technique. Why that mapping matters, and how the 35 scenarios line up against the framework.

22 August 2026 · 7 min
Methodology

Reading a simulation result: kill-chain, viable path, exposure score

How to read a simulation: the kill-chain of a scenario, what makes a path viable, the break point, and how the exposure score is built.

20 August 2026 · 7 min
Security

The EntraGUARD attack simulator: 35 known attacks, replayed read-only

EntraGUARD replays 35 known Entra ID & M365 attacks against the tenant, strictly read-only — each a kill-chain with a verdict and an exposure score.

18 August 2026 · 8 min
Methodology

Install and customize EntraGUARD: from setup to white-label

Step by step: install EntraGUARD on a workstation, then make it yours — white-label branding, per-client logos, offline licence, themes.

26 July 2026 · 7 min
MSP

The security assessment checklist for MSPs

A repeatable checklist for running Microsoft security assessments across several clients, and packaging it as a service.

21 July 2026 · 9 min
MSP

Building a recurring audit offer rather than a one-off audit

Framing, initial audit, remediation plan, follow-up audit, quarterly committee: the sequence that turns an engagement into a subscription.

14 July 2026 · 8 min
Compliance

HIPAA: auditing the technical safeguards on the Microsoft side

How the HIPAA Security Rule's technical safeguards map to Microsoft configuration, and how to evidence them.

7 July 2026 · 8 min
Compliance

CMMC and NIST SP 800-171: auditing Microsoft identity

How the access control and authentication requirements of NIST SP 800-171 and CMMC map to Microsoft configuration.

30 June 2026 · 9 min
Compliance

Microsoft security audit for SOC 2 compliance

How a configuration audit produces the technical evidence auditors ask for under SOC 2 Trust Services Criteria CC6 and CC7.

16 June 2026 · 9 min
Methodology

Detecting drift between two audits

An identical score can hide an estate that has moved. Comparing findings resource by resource reveals what the verdict does not say.

9 June 2026 · 7 min
Reports

Which report for which audience

Management, technical team, project manager, external auditor: one audit, four to six different renderings, and five file formats.

28 April 2026 · 8 min
Compliance

Security audits for NIS2 and ISO 27001 compliance

How a Microsoft configuration audit supports a NIS2 or ISO 27001 programme with dated, defensible evidence.

7 April 2026 · 7 min
Security

Top 10 Entra ID misconfigurations to fix first

The ten most common and most dangerous Entra ID misconfigurations, why they matter, and how to remediate each one.

24 March 2026 · 9 min
Methodology

Custom baselines: adapting the audit to your context

Building a baseline: set aside out-of-scope controls, adjust criticality, and make the score reflect your real requirements.

17 March 2026 · 6 min
Methodology

Dedicated audit vs Microsoft Secure Score: what changes

Microsoft Secure Score is useful but limited. What a dedicated audit goes on to find, and the action plan it produces.

10 March 2026 · 7 min
Methodology

Understanding the weighted compliance score (L1/L2)

Why a weighted score reflects real risk better than a simple pass ratio, and how level 1 and level 2 controls are weighted in the calculation.

3 March 2026 · 6 min
Methodology

The 494 controls explained: CIS, ANSSI, NIST and ISO 27001

How the 494 automated controls of the two GUARD tools map to CIS, ANSSI, NIST and ISO 27001, and why that alignment makes an audit defensible.

24 February 2026 · 9 min
Connectors

Configuring the Entra ID connector: every authentication method explained

Connect the audited tenant step by step: automatic provisioning, certificate vs client secret, and the read-only Graph permissions required.

3 February 2026 · 8 min
The whole blog
All 27 articles, across every referential.
See everything →